CVE-2026-81999: Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)
Published Sep 22, 2026
·Updated
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
1 affected component
Adobe Experience Manager Forms JEE
Event History
Sep 22, 2026
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires an attacker to already hold high privileges in Adobe Experience Manager Forms JEE. No user interaction is required.
2
What is the likely impact of successful exploitation?
A successful attacker could use server-side request forgery to gain elevated access to internal resources. The vulnerability has changed scope and is rated high severity.